The are numerous ways to modify the LDAP query to limit the number of users returned and therefore added to PureCloud. For example adding (manager =*) will only select users that have a manager. There are numerous websites that describe in detail how to use LDAP queries with AD.
The frequency Sync operations with AD is controlled by a delay in seconds specified in the connector configuration. Typically synchronizing once an hour is sufficient for most companies.
The AD connector will recognizes changes for any user in PureCloud or AD. These changes are propagated to the other system depending on the configuration. For example: it might be desirable to have a user's title sync only from AD to PureCloud, their work phone to update in either direction and have their cell phone updated only from PureCloud to AD. This is fully configurable in the connector UI.
If a user is added to PureCloud manually then the AD connector will ignore it. However, if the user has the same email address in PureCloud and AD then the AD connector will take over synchronization of that user.
Users created in PureCloud by the AD connector will be deleted from PureCloud if and when they are deleted from AD. Note "deleted from AD" technically means no longer shows up in an LDAP query.